Phishing Hack

TOTAL LOST $2.5M
Medium Phishing Attacks

What happened

On October 10, 2024, a phishing attack led to the loss of $2.47 million in Aave Ethereum sDAI after a user unknowingly signed a malicious "permit" signature.

The victim signed a fraudulent "permit" transaction that allowed the scammer to gain control of the sDAI tokens. The scam involved temporary addresses pre-computed using the CREATE2 function, commonly used in phishing schemes to deceive victims into granting access to their assets.

Victim Address: 0xfcc5acd5…d403c2

Scammer Address: 0xAc68803B…67E7f2

Transaction Hash: https://etherscan.io/tx/0x64a00980…86454f

Case & protocol details

Classification Other
Protocol Type Exploit/Phishing

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.